Lettuce Encrypt, Encrypt We Must: Hobby projects change name after Let's Encrypt fires off trademark complaints
- Reference: 1591793530
- News link: https://www.theregister.co.uk/2020/06/10/lets_encrypt_trademark_complaints/
- Source link:
[1]ISRG is nonprofit sponsored by numerous companies including the Electronic Frontier Foundation, Google, Cisco, Mozilla, Facebook, IBM, VMware, Akamai, and [2]Microsoft-owned GitHub . Its purpose is to promote secure internet connections, its main project being Let's Encrypt. Using the Let's Encrypt service, anyone can obtain a free SSL certificate so that it costs nothing to support encrypted connections on a website. Let's Encrypt issued its first certificate in 2015.
[3]
Let's Encrypt now certifies over 220 million active domains
Let's Encrypt has been hugely popular, and has now certified over 220 million active domains, according to its [4]statistics , but has some inconveniences, notably that its certificates expire after 90 days. The idea is to reduce the risk from compromised certificates, and to encourage [5]automated renewal .
The primary tool for obtaining a Let's Encrypt certificate is a script called [6]certbot , but for a long time this did not work on Windows. Although there is now a Windows version, it has limitations like the inability to update the webserver automatically. It was designed with Unix-like operating systems in mind and has always been a tad awkward for Windows users. The availability of other scripts has improved since the early days; many are [7]listed here , some specifically for Windows.
Nate McMaster worked at Microsoft when Let's Encrypt was launched (he is now a software development engineer at AWS) and started a "hobby project" to provide a Let's Encrypt API for ASP.NET core applications. "When enabled, your web server will automatically generate an HTTPS certificate during startup," explain the docs. "It then configures Kestrel to use this certificate for all HTTPS traffic." Kestrel is the default ASP.NET web server. He called the project ASP.NET Core + Let's Encrypt. McMaster's solution does not actually auto-renew certificates according to a schedule, though this is a possible forthcoming feature.
It seems that ISRG considered that the project did not conform to its [8]trademark policy . "Earlier versions of this package were named 'McMaster.AspNetCore.LetsEncrypt', a name selected from combining my family name, the web framework for .NET Core, and the most widely used certificate authority that implements the ACME protocol, which is 'Let's Encrypt®', of course," McMaster explained on the project's [9]GitHub issues page .
"This was started as a hobby project years ago and I never thought the naming would be a problem. This project drew the attention of the Internet Security Research Group (ISRG)™️, which runs Let's Encrypt. They informed me last week that they considered my original project name a violation of their trademarks. As this code is not an official offering of ISRG and I want to support their efforts to run Let's Encrypt, I have complied with their request to rename the project."
The name he chose is Lettuce Encrypt – "100% organic and best served cold with ranch and carrots."
It is unfortunately a breaking change but should require "minimal effort" to upgrade. The old version is still available from nuget.org, the .NET package repository, but is now unsupported. In December, McMaster considered abandoning the project because of similar competing solutions, but following feedback [10]decided to "keep working on this project" and invited feature suggestions.
The main similar project McMaster had in mind is called "AspNet.EncryptWeMust" (which does auto-renew) and guess what? "This project used to be called FluffySpoon.AspNet.LetsEncrypt, but due to a trademark claim from LetsEncrypt, we had to rename it. The name now follows Yoda Speak," [11]says maintainer Mathias Lykkegaard Lorenzen.
Whether Lettuce Encrypt is useful depends on the exact hosting scenario. It only works for Kestrel, and not when the application is behind IIS, the Windows web server (though note that ASP.NET Core is cross-platform and also runs well on Linux). It does not work with Azure App Service (though the Yoda-Speak alternative does), perhaps the most common way to deploy an ASP.NET Core application to Microsoft's cloud.
There are other options, such as Simon Pedersen's Let's Encrypt [12]Site Extension . In addition, paying Azure customers can get free SSL certificates from DigiCert via Microsoft's [13]App Service Managed Certificates , now in preview. A limitation of Microsoft's official service is that it does not support naked domains; developers must use a prefix such as www.
Heavy-handed or just going through the motions needed to protect its trademark? We have asked ISRG for comment. ®
Sponsored: [14]Running Your Modern .NET Application on Kubernetes
[1] https://www.abetterinternet.org/
[2] https://www.theregister.com/2018/06/04/microsoft_buys_github/
[3] https://regmedia.co.uk/2020/06/10/letsencrypt.png
[4] https://letsencrypt.org/stats/
[5] https://community.letsencrypt.org/t/pros-and-cons-of-90-day-certificate-lifetimes/4621
[6] https://certbot.eff.org/
[7] https://letsencrypt.org/docs/client-options/
[8] https://letsencrypt.org/trademarks/
[9] https://github.com/natemcmaster/LettuceEncrypt/issues/99
[10] https://github.com/natemcmaster/LettuceEncrypt/issues/29#issuecomment-587276452
[11] https://github.com/ffMathy/FluffySpoon.AspNet.EncryptWeMust
[12] https://github.com/sjkp/letsencrypt-siteextension
[13] https://azure.microsoft.com/en-us/updates/secure-your-custom-domains-at-no-cost-with-app-service-managed-certificates-preview/
[14] https://go.theregister.com/tl/1956/-8477/running-your-modern-net-application-on-kubernetes?td=wptl1956
Re: US "defend your rights" Requirement?
I believe it does, which is probably their driving force here, I would assume.
Re: US "defend your rights" Requirement?
Added to which we don't want crooks and scammers to be able to use the name to con people.
Re: US "defend your rights" Requirement?
Not only the US as far as I know. Trademarks are everywhere "defend or lose".
It's different from copyright, which you can't lose.
> Kestrel is the default ASP.NET web server.
No it isn't. Kestrel is the default web server for ASP.Net Core.
I didn't know that I thought they would be the same
I suppose there could be a spoofing problem - if a project has LetsEncrypt in its name it might be trusted without further investigation by the unwary and then go on to load something untrustworthy with LetsEncrypt then catching the blame. So, yes, I can see why they would take that line.
"Heavy-handed or..."
Of course not! They have to protect their trademark or others could leech off it and severely dent their profit margin.
ISRG is nonprofit... . Oh. Right. Just heavy-handed then.
Almost all the internet belongs to me (and not Montenegro)
At primary school I once left off the final letter of 'come' in an essay. Does this mean i can now claim copyright theft by ICANN's leading registry?
US "defend your rights" Requirement?
Is the ISRG based in the US? Doesn't the US have some requirements for folks to "defend-it-or-lose-it" on various IP "rights"?